Hoppa till innehåll
Terms

General Terms and Data Processing Agreement

These terms apply to our services for businesses. As a customer you accept them, together with your Order Confirmation, when you sign in the customer portal. The Swedish version prevails.

General Terms and Conditions

Version 2026-09-25

These general terms and conditions apply when Svensk Synlighet provides services to customers that are businesses. Svensk Synlighet is operated by Sowandox AB, company reg. no. 559457-8097 ("the Supplier"). This is a translation; in case of discrepancy the Swedish version prevails.

1. The agreement and its components

The agreement between the Supplier and the customer ("the Customer") consists of (a) the Order Confirmation approved by the Customer, (b) the data processing agreement and (c) these general terms and conditions. In the event of any inconsistency between these components, they take precedence in that order, except in matters concerning personal data, where the data processing agreement always takes precedence.

The agreement is entered into when the Customer approves the Order Confirmation in the Supplier's customer portal or otherwise in writing. Electronic approval in the customer portal has the same effect as a signature on paper.

The Services are intended for businesses. Any person approving the agreement on the Customer's behalf warrants that they are authorised to represent the Customer.

2. The Services

The Supplier offers, among other things, development of websites, web apps and other digital systems, operations and maintenance (operations packages), social media management (social media packages), advertising management, and support and advisory services ("the Services"). What is included for the Customer is set out in the Order Confirmation and in the package descriptions applicable when the agreement is entered into.

The Supplier performs the Services in a professional manner and uses its own staff, subcontractors and modern tools, including AI tools. The Supplier is responsible for the work of subcontractors as for its own.

Extensions and changes are ordered via the customer portal (by submitting a ticket), by email or through a new Order Confirmation. Work beyond what is included in a package or a fixed-price assignment is charged by the hour in accordance with section 3.

3. Prices

Unless otherwise stated in the Order Confirmation, the Supplier's price list applicable from time to time at https://www.svensksynlighet.se/priser applies. All prices are stated exclusive of VAT.

Work charged by the hour is reported on an ongoing basis and can be followed in the customer portal. Time is rounded as stated in the Order Confirmation. A time estimate or quotation is an estimate and not a fixed price, unless it is expressly stated that the price is fixed.

Where a fixed price applies, the price covers the scope described in the Order Confirmation. Instalments (milestones) are invoiced when the respective milestone has been delivered or at the times stated. Changes to the scope are charged by the hour after the Customer's approval.

Usage beyond what is included in a package (for example bandwidth, email, SMS and AI usage in the Customer's systems) is charged at the unit prices in the price list.

Third-party costs ordered by the Customer, for example advertising budgets with Google or Meta, domain names beyond those included in the package, or licences, are paid by the Customer and are never included in the package price unless otherwise stated.

The Supplier may change prices for recurring services (packages, hourly rate and unit prices) by notifying the Customer at least 30 days in advance. The Customer may then terminate the affected service with effect from the date on which the change comes into force.

4. Invoicing and payment

Monthly packages are invoiced monthly for the month to which they relate. Hourly work and usage are invoiced in arrears, normally monthly. If a service starts part-way through a month, the amount may be added to the following month's invoice.

Payment terms are 14 days net unless otherwise agreed. In the event of late payment, the Supplier is entitled to default interest under the Swedish Interest Act (räntelagen) (the reference rate plus 8 percentage points), a reminder fee of SEK 60 and late payment compensation of SEK 450 under the Swedish Act on Compensation for Debt Recovery Costs.

If an invoice remains unpaid more than 30 days after the due date and the Customer has received a reminder, the Supplier may suspend the Services until payment is made. The Supplier shall notify the Customer at least five business days before any suspension.

Any objections to an invoice must be raised within the payment period. Undisputed amounts must be paid on time.

5. The Customer's obligations

The Customer shall provide, in good time, the material, information, access and decisions required for the Services, for example texts, images, login credentials and approvals. Delays attributable to the Customer may shift timelines and may result in additional costs.

The Customer is responsible for ensuring that material provided or approved by the Customer (for example images, texts, trademarks and posts) does not infringe the rights of others and does not violate the law. The Customer shall indemnify and hold the Supplier harmless if a third party brings claims on account of such material.

The Customer is responsible for keeping its login credentials for the customer portal and other systems secure and shall notify the Supplier without delay if unauthorised access is suspected.

Social media content is published after the Customer's approval. Approved content is deemed to be the Customer's own.

6. Intellectual property rights

Once the Customer has paid for a piece of work, the Customer obtains ownership of the material produced specifically for the Customer, for example the Customer's design, texts and the customer-specific code in the Customer's website or systems.

The Supplier retains the rights to generic components, tools, templates, libraries and know-how that the Supplier also uses for other customers. The Customer is granted a perpetual, non-exclusive right to use such parts as are included in the Customer's deliverables.

Open-source software and third-party services are subject to their own licence terms.

The Supplier may name the Customer as a reference and showcase delivered work (for example screenshots and a link) in its marketing, unless the Customer notifies the Supplier in writing that it does not wish this.

7. Operations, maintenance and availability

The operations packages include what is described in the package description, for example hosting, security updates, monitoring and support. The Supplier aims for high availability but gives no uptime guarantees unless a specific level has been agreed in writing.

The Services rely in part on third-party platforms (for example hosting, databases, email and advertising platforms). The Supplier is not responsible for outages or changes on such platforms but works to limit the consequences for the Customer.

Planned maintenance is, where possible, carried out at times when the impact on the Customer is low.

8. Personal data and confidentiality

When the Supplier processes personal data on behalf of the Customer, the Supplier is the processor and the Customer is the controller. The processing is governed by the data processing agreement, which forms part of the agreement.

The parties shall keep confidential information received from the other party secret and use it only to perform the agreement. The confidentiality obligation applies during the term of the agreement and for three years thereafter. It does not apply to information that is publicly known or that a party is required to disclose by law.

9. Defects in deliverables

The Customer shall give notice of any defect in a deliverable within a reasonable time after the defect was discovered, and no later than 90 days after delivery. The Supplier shall remedy defects for which the Supplier is responsible within a reasonable time at no extra cost.

Defects caused by the Customer, by changes made by anyone other than the Supplier, or by third-party services are remedied against payment at the hourly rate.

10. Limitation of liability

The Supplier is liable only for direct loss caused by the Supplier's negligence. The Supplier is not liable for indirect loss, for example loss of profit, loss of revenue, loss of production or loss of data that the Customer could have backed up.

The Supplier's aggregate liability under the agreement is limited to an amount corresponding to what the Customer has paid for the Services during the twelve months preceding the event that caused the loss.

These limitations do not apply in cases of wilful misconduct or gross negligence, nor to liability under the GDPR to the extent that such liability may not be limited.

Claims must be made in writing within six months of the loss being discovered or when it ought to have been discovered.

11. Force majeure

A party is released from any sanction for failure to perform an obligation if the failure is due to a circumstance beyond the party's control which the party could not reasonably have foreseen, for example war, decisions by public authorities, extensive disruptions to electricity, telecommunications or internet services, cyberattacks on third parties, or failures on the part of a subcontractor caused by such a circumstance.

12. Term and termination

The agreement applies until further notice from the time it is entered into, unless the Order Confirmation states otherwise. There is no minimum commitment period for hourly work.

Monthly packages may be terminated by either party with one (1) month's notice, effective at the end of a calendar month, unless the Order Confirmation states otherwise. A fixed-price assignment runs until it has been delivered; if the Customer terminates it early, work performed is charged by the hour, but not exceeding the fixed price.

Notice of termination shall be given in writing, for example by email or by submitting a ticket in the customer portal.

A party may terminate the agreement with immediate effect if the other party materially breaches the agreement and fails to remedy the breach within 30 days of written notice, or if the other party is declared bankrupt, enters into company reorganisation or may otherwise be assumed to be insolvent.

When the agreement ends, the Supplier shall hand over the Customer's material, code, domain names and access credentials to which the Customer is entitled, once all invoices have been paid. Work on handover and migration to another supplier is charged by the hour. Data stored by the Supplier on the Customer's behalf is deleted in accordance with the data processing agreement.

13. Changes to the terms

The Supplier may amend these general terms and conditions. The Customer will be notified of amendments at least 30 days before they take effect, via the customer portal or by email. If the Customer does not wish to accept an amendment, the Customer may terminate the agreement with effect from the date on which the amendment takes effect.

14. Assignment

The Customer may not assign the agreement without the Supplier's written consent. The Supplier may assign the agreement to a company within the same group or to whoever takes over the business operated under the Svensk Synlighet brand, for example Svensk Synlighet AB, and shall then notify the Customer.

15. Notices

Notices under the agreement are given via the customer portal or by email to the addresses provided by the parties. The Supplier can be reached at info@sowandox.com.

16. Governing law and disputes

The agreement is governed by Swedish law. Disputes shall primarily be resolved through negotiation. If the parties cannot reach agreement, the dispute shall be settled by the general courts, with Lund District Court as the court of first instance.

Data Processing Agreement

Version 2026-09-25

This data processing agreement forms part of the agreement between the Customer (controller) and Sowandox AB, company reg. no. 559457-8097, which operates Svensk Synlighet (processor, "the Supplier"). It applies when the Supplier processes personal data on behalf of the Customer. This is a translation; in case of discrepancy the Swedish version prevails.

1. Purpose and scope

The Supplier processes personal data on behalf of the Customer to the extent necessary to deliver the Services, for example operating the Customer's website and systems, contact forms, email, SMS, visitor statistics, advertising management and publishing on social media.

The processing continues for as long as the agreement is in force and thereafter for the period necessary for return and deletion in accordance with section 10.

2. Categories of data subjects and personal data

Data subjects: visitors to the Customer's website, the Customer's customers, members and contact persons, and the Customer's employees and users of the Customer's systems.

Personal data: contact details (name, email, telephone, address), information that data subjects themselves provide in forms, bookings and tickets, account details and login data, technical data such as IP address, device and browser information and usage statistics, and the content of emails and messages.

The Customer shall not allow the Supplier to process sensitive personal data or personal identity numbers unless this has been specifically agreed.

3. The Customer's instructions

The Supplier processes the personal data only on the Customer's documented instructions. The agreement, the Order Confirmation and the settings and orders the Customer makes via the customer portal or in writing constitute the Customer's instructions.

The Supplier shall inform the Customer if the Supplier considers that an instruction infringes the GDPR or other data protection legislation.

The Customer is responsible for ensuring that there is a legal basis for the processing and for informing the data subjects, for example through a privacy policy on the Customer's website.

4. Confidentiality

The Supplier ensures that the persons who have access to the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and that they process the data only in accordance with the Customer's instructions.

5. Security

The Supplier implements appropriate technical and organisational measures to protect the personal data, including encrypted transmission (HTTPS/TLS), access control ensuring that only those who need access have it, two-factor authentication for administrative access, logging of administrative actions, regular security updates and backups where included in the Service.

The Supplier reviews the measures regularly and adapts them to risks and technical developments.

6. Sub-processors

The Customer grants the Supplier general prior authorisation to engage sub-processors. The Supplier enters into written agreements with sub-processors that provide protection equivalent to that of this agreement and is liable to the Customer for the sub-processors' processing.

Sub-processors at the time the agreement is entered into, depending on which Services the Customer uses: Vercel Inc. (hosting and server functions, EU region), Google Cloud/Firebase (database, authentication and file storage, EU region), Google LLC (Google Analytics and Google Ads, where included), Resend Inc. (sending emails from websites and systems), Migadu (email accounts), 46elks AB (SMS), Cloudflare Inc. (DNS), Functional Software Inc./Sentry (error monitoring; personal data is filtered out as far as possible), OpenRouter Inc. and the AI models accessed through it (AI features in the customer portal and in the Customer's systems, where included), Day Moon Inc./Post for Me (scheduled publishing on social media) and Meta Platforms and LinkedIn (publishing and advertising, where included).

The Supplier shall inform the Customer via the customer portal or by email at least 30 days before a new sub-processor is engaged or an existing one is replaced. The Customer may object on objective grounds. If the parties cannot reach agreement, the Customer may terminate the affected Service.

7. Transfers to third countries

Certain sub-processors are based in the USA or process data there. Transfers to countries outside the EU/EEA take place only on the basis of an adequacy decision (for example the EU–US Data Privacy Framework for certified companies) or the European Commission's standard contractual clauses, with supplementary measures where necessary.

8. Assistance to the Customer

The Supplier assists the Customer, insofar as possible, in responding to requests from data subjects (for example for access, rectification or erasure) and in fulfilling obligations concerning security, impact assessments and prior consultation.

Assistance beyond what is normally included in the Services is charged by the hour in accordance with the agreement.

9. Personal data breaches

The Supplier shall notify the Customer without undue delay, and where possible within 48 hours, after becoming aware of a personal data breach affecting the Customer's data. The notification contains the information the Customer needs in order to assess the breach and, where necessary, report it to the Swedish Authority for Privacy Protection (IMY).

10. Return and deletion

When the agreement ends, the Supplier deletes the Customer's personal data, or returns it if the Customer so requests before the agreement ends. Deletion takes place within 90 days, unless the law requires the data to be retained for longer. Data in backups is deleted when the backups are rotated out.

11. Audits

The Supplier provides the Customer with the information necessary to demonstrate compliance with this agreement. The Customer may, after giving at least 30 days' prior written notice, have an independent auditor bound by a duty of confidentiality verify compliance. The Customer bears its own costs and compensates the Supplier for its work by the hour.

12. Liability and term

The allocation of liability and the limitation of liability in the general terms and conditions also apply to this agreement, to the extent permitted by the GDPR.

This agreement applies for as long as the Supplier processes personal data on behalf of the Customer.